
The Personal Information Protection Commission (PIPC), South Korea's data protection authority, has imposed a record fine of 624.6 billion won (approximately $409 million) on e-commerce giant Coupang following a significant data breach that impacted over 37 million customers.
Its subsidiary, Coupang Fulfillment Service, was also penalized 248 million won for unlawfully collecting, utilizing, and managing customers' personal and sensitive information.
Investigators determined that the personal data of roughly 37.55 million individuals was exposed due to insufficient security measures, including lapses in authentication key management and access controls.
The PIPC additionally cited breaches of data destruction and leak-notification obligations, interference with the autonomy of Coupang's data protection officer, and obstruction of the investigation.
"Personal information of approximately 37.55 million people leaked due to insufficient basic safety management system, including negligence in authentication signature key management and access control," the PIPC stated. "Regarding Coupang's violation of safety measure obligations and collection of personal information without legal basis, a fine of 624.681 billion won and a fine of 16.8 million won were imposed, as well as corrective orders, announcements, and publication orders."
Coupang is an American online retail firm operating in the South Korean market, employing 95,000 people and reporting annual revenues exceeding $30 billion.
In late December, the company announced plans to pay 1.685 trillion won (approximately $1.17 billion) and to begin distributing single-use purchase vouchers totaling 50,000 won (about $34) per customer in January 2026 to compensate over 33 million affected users.
This breach, among the most severe in South Korea's history, occurred in late June but was only discovered in mid-November, when the company warned that 33.7 million accounts had been compromised.
According to South Korean authorities, who took over the investigation, the primary suspect is a 43-year-old Chinese national who worked in Coupang's IT department from 2022 to 2024.
Coupang later stated that the former employee returned multiple hard drives containing sensitive data. The suspect also disposed of a MacBook Air laptop in a river in an attempt to destroy evidence, but the device was recovered. Coupang added that the suspect retained user data for approximately 3,000 accounts, despite accessing millions, and that this data was deleted from all devices and not transferred to others.
SK Telecom, South Korea's largest mobile network operator, also warned customers in April that sensitive USIM data had been exposed after its network was infected with malware. The company later revealed the malware was first deployed on its systems in June 2022, affecting a total of 27 million subscribers (representing nearly all of SK Telecom's customer base).
Test every layer before attackers do
Security teams log 54% of successful attacks and alert on just 14%. The rest move through your environment unseen.
The Picus whitepaper shows how breach and attack simulation tests your SIEM and EDR rules so threats stop slipping by detection.
Related Articles:
UK fines LastPass over 2022 data breach impacting 1.6 million users
Ex-school district employee jailed for hacks on former employer
Maine disables data breach notification portal after fake disclosures
Japanese energy firm loses drive with data of 10.9 million clients
Pharma giant Novo Nordisk discloses breach of clinical trials data